LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Banco Comercial do Huambo was hacked Africa's most insecure bank has leaked a huge amount Listed by alphv Ransomware Group

HIGH severityUnverified claimHow we verify

Banco Comercial do Huambo was hacked Africa's most insecure bank has leaked a huge amount Listed by alphv Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·April 21, 2023
Banco Comercial do Huambo was hacked Africa's most insecure bank has leaked a huge amount Listed by alphv Ransomware Group

Reported April 21, 2023.

HIGH
Severity
April 21, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Banco Comercial do Huambo was hacked Africa's most insecure bank has leaked a huge amount Listed by alphv Ransomware Group (reported April 21, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to single out financial institutions across regions where digital banking is expanding faster than defensive capacity. In that setting, a April 2023 listing by the alphv ransomware group placed Banco Comercial do Huambo, an Angolan bank headquartered in Luanda, among the organisations claimed as victims. Public detail remains limited, yet any confirmed or claimed compromise of a bank raises immediate questions about the safety of customer records and internal operations.

What is known so far is modest: the group asserted that it had exfiltrated internal files in a ransomware attack and listed the bank on its leak site. No independent confirmation of the full scope has been widely published, the number of people affected is unknown, and precise technical methods beyond the ransomware label have not been disclosed. The episode still matters because banks sit at the centre of personal and commercial finance; even partial exposure of internal material can create lasting risk for customers and counterparties.

What happened

According to reporting dated 21 April 2023, Banco Comercial do Huambo appeared on the leak site operated by the alphv ransomware group. The group claimed the bank had been hacked and that internal files had been exfiltrated as part of a ransomware attack. One accompanying characterisation described the institution as “Africa’s most insecure bank” and asserted that “a huge amount” of material had been leaked; these statements originate with the threat actors and remain unverified claims rather than independently established facts.

No public figure has been given for the volume of data taken, the number of individuals whose information may be involved, or the exact date the intrusion began. The method of initial access, the duration of presence inside the network, and whether encryption was successfully deployed have not been detailed in available records. In short, the incident is documented principally through the group’s own listing and the high-level description that internal files were removed during a ransomware operation.

Inside alphv

Alphv, also widely known as BlackCat, is a ransomware-as-a-service operation that became prominent in late 2021. The group typically recruits affiliates who conduct intrusions, then supplies them with customisable ransomware written in Rust and a platform for negotiating ransoms and publishing stolen data. Its hallmark is double extortion: data is copied before systems are encrypted, and the threat of public release is used to pressure victims even if backups allow recovery.

Alphv has previously claimed attacks against organisations in healthcare, manufacturing, government and finance across multiple continents. Affiliates often exploit stolen credentials, unpatched vulnerabilities or phishing to gain footholds, then move laterally and stage large-scale exfiltration. When negotiations stall, the group posts victim names and sample files on its Tor-based leak site. Because the listing of Banco Comercial do Huambo is itself such a claim, it should be treated as an assertion by the actors rather than confirmed evidence of every detail they advertise.

About Banco Comercial do Huambo

Banco Comercial do Huambo is a commercial bank headquartered in Luanda, Angola. Public records associated with the incident describe it as operating in the civic and social organisation sector, yet its name and function place it squarely in retail and commercial banking. Like peer institutions, it maintains customer accounts, payment systems, credit facilities and the internal administrative records required to run a regulated financial business.

A breach affecting any bank is consequential because the organisation necessarily holds sensitive personal and financial information and sits inside national payment rails. Disruption or data exposure can affect depositors, borrowers, employees and partner institutions. In markets where banking access is still expanding, trust in the security of those services is especially important; an incident, even one whose full scope remains unconfirmed, can erode that trust and invite closer regulatory scrutiny.

What data was at risk

The only data category named in available reporting is “internal files” said to have been exfiltrated in the ransomware attack. No inventory of file types, databases or record counts has been published. Exact contents therefore remain unconfirmed.

Organisations of this kind ordinarily store customer identification documents, account and transaction histories, credit files, employee records, internal financial reports, contracts and system configuration data. Any of those categories could theoretically have been among the internal files the group claims to possess. Until a fuller disclosure or independent analysis appears, however, it is not possible to state which specific data sets were taken or how many individuals are involved.

What's at stake

For customers and employees, the principal risks are secondary misuse of personal or financial information—account takeover attempts, targeted phishing that references real banking relationships, identity fraud, or unsolicited approaches that exploit leaked contact details. Even when core banking ledgers remain intact, internal correspondence or supporting documents can supply criminals with enough context to craft convincing social-engineering attacks.

For the bank itself, stakes include operational disruption if systems were encrypted, potential regulatory obligations to notify authorities and customers, reputational damage, and the cost of forensic investigation and remediation. Because the number of people affected is unknown and the precise data unconfirmed, the practical impact cannot yet be quantified; the prudent assumption is that any individual or business that has held an account or conducted significant business with the institution should treat the possibility of exposure seriously until clearer information emerges.

Were you affected?

If you hold or have held an account, loan or other relationship with Banco Comercial do Huambo, begin by monitoring account statements and transaction alerts for unfamiliar activity. Change online-banking and email passwords, enable multi-factor authentication wherever it is offered, and treat unexpected messages that reference the bank with caution. Consider placing fraud alerts with relevant credit bureaus if that service is available in your jurisdiction. Keep records of any suspicious contacts.

You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. That step will not confirm or rule out involvement in this specific incident, but it provides a practical starting point for understanding your wider exposure and deciding what further monitoring is warranted.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyBanco Comercial do Huambo security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Banco Comercial do Huambo’s full breach history →

More recent breaches

Cosal is a company that distributes personal and confidential data of its customers and re Listed by alphv Ransomware GroupSeptember 21, 2023QSI INC - Credit Cards & Transaction Processing Listed by alphv Ransomware GroupOctober 15, 2023Progressive Leasing ( 40 million Customers PII Data ) Listed by alphv Ransomware GroupSeptember 22, 2023ende.co.ao is a company you can test corporate network hack on and have 100% hacking succe Listed by alphv Ransomware GroupSeptember 21, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the Banco Comercial do Huambo was hacked Africa's most insecure bank has leaked a huge amount Listed by alphv Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by alphv — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram